Cross-Site Scripting Vulnerability in Sourcecodester FAQ Bot with AI Assistant
CVE-2025-63639

6.1MEDIUM

Key Information:

Vendor
CVE Published:
7 November 2025

What is CVE-2025-63639?

The chat functionality in the Sourcecodester FAQ Bot with AI Assistant v1.0 is susceptible to Cross-Site Scripting (XSS) vulnerabilities. This security flaw arises from inadequate sanitization of user-supplied input, allowing attackers to inject harmful HTML or JavaScript scripts into chat messages. Once injected, these scripts can execute in the browsers of other users participating in the conversation, potentially compromising sensitive information and leading to further exploitation. Proper validation and encoding of user inputs are essential to mitigate this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.